CVE-2020-6463: Use After Free
Crafted media files could lead to a race in texture caches, resulting in a use-after-free, memory corruption, and a potentially exploitable crash.
Other sources
Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
— Launchpad
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-6463?
CVE-2020-6463 is a vulnerability in Mozilla Firefox and Thunderbird that could lead to a use-after-free memory corruption and a potentially exploitable crash.
How severe is CVE-2020-6463?
CVE-2020-6463 has a medium severity rating.
Which software is affected by CVE-2020-6463?
Mozilla Firefox ESR versions up to 68.11, Thunderbird versions up to 68.11, Firefox versions up to 79, Firefox ESR versions up to 78.1, and Thunderbird versions up to 78.1 are affected.
How can CVE-2020-6463 be exploited?
CVE-2020-6463 can be exploited using crafted media files that lead to a race in texture caches.
How can I fix CVE-2020-6463?
To fix CVE-2020-6463, users should update Mozilla Firefox and Thunderbird to the recommended versions.